gatesnapper.dll

gate snapper

Part of the Yontoo adware component, a web browser plugin that injects unwanted ads in the browser. The module gatesnapper.dll by gate snapper has been detected as adware by 9 anti-malware scanners. This file is typically installed with the program gate snapper by Yontoo Technology, Inc. which is a potentially unwanted software program. It will plug into the web browser and display context-based advertisements by overwriting existing ads or by inserting new ones on various web pages. The file has been seen being downloaded from install-cdn.gatesnapper.com.
Publisher:
gate snapper  (signed and verified)

Product:
gate snapper

Version:
1.0.0.7

MD5:
8d867412a7ea67d13a480f2b1f9d7c0d

SHA-1:
fd86a1ab54662cf6c5378efedfc4d7e4ad85825b

SHA-256:
9880010b1f0beaa09d17998ba09293c89bbffbac69a8248d80523599f9d05423

Scanner detections:
9 / 68

Status:
Adware

Explanation:
Injects advertising in the web browser in various formats.

Analysis date:
12/27/2024 7:29:45 AM UTC  (today)

Scan engine
Detection
Engine version

Avira AntiVirus
ADWARE/BrowseFox.Gen2
7.11.209.90

AVG
Generic
2016.0.3202

Baidu Antivirus
Adware.Win32.BrowseFox
4.0.3.15210

Bkav FE
W32.HfsAdware
1.3.0.6379

ESET NOD32
Win32/BrowseFox.AE potentially unwanted (variant)
9.11155

IKARUS anti.virus
AdWare.BrowseFox
t3scan.1.8.6.0

Malwarebytes
PUP.Optional.GateSnapper.A
v2015.02.10.06

NANO AntiVirus
Trojan.Win32.Yontoo.dnkubo
0.30.0.65070

Reason Heuristics
PUP.Yontoo
15.2.10.17

File size:
262.7 KB (269,048 bytes)

Product version:
1.0.0.7

Copyright:
(c) gate snapper. All rights reserved.

File type:
Dynamic link library (Win32 DLL)

Language:
English (United States)

Common path:
C:\users\{user}\appdata\local\microsoft\windows\inetcache\content.ie5\rudq5lgt\gatesnapper.dll

Digital Signature
Signed by:

Authority:
VeriSign, Inc.

Valid from:
11/19/2014 6:00:00 PM

Valid to:
11/20/2015 5:59:59 PM

Subject:
CN=gate snapper, O=gate snapper, L=Santa Monica, S=California, C=US

Issuer:
CN=VeriSign Class 3 Code Signing 2010 CA, OU=Terms of use at https://www.verisign.com/rpa (c)10, OU=VeriSign Trust Network, O="VeriSign, Inc.", C=US

Serial number:
133A7A0373BA5F8F11B450D044B92146

File PE Metadata
Compilation timestamp:
2/7/2015 12:42:04 PM

OS version:
6.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
11.0

CTPH (ssdeep):
3072:LmiYckxqEbUViVqUsVNXBB+/nFK3wY+lx9ZKT0hKjscEJ:LmiYckziiVMrXFdI9Z/Yz+

Entry address:
0xF515

Entry point:
55, 8B, EC, 83, 7D, 0C, 01, 75, 05, E8, EA, 7E, 00, 00, FF, 75, 10, FF, 75, 0C, FF, 75, 08, E8, 07, 00, 00, 00, 83, C4, 0C, 5D, C2, 0C, 00, 6A, 0C, 68, D8, 21, 03, 10, E8, 4C, 02, 00, 00, 33, C0, 40, 8B, 75, 0C, 85, F6, 75, 0C, 39, 35, 4C, 77, 03, 10, 0F, 84, E4, 00, 00, 00, 83, 65, FC, 00, 83, FE, 01, 74, 05, 83, FE, 02, 75, 35, 8B, 0D, C4, 93, 02, 10, 85, C9, 74, 0C, FF, 75, 10, 56, FF, 75, 08, FF, D1, 89, 45, E4, 85, C0, 0F, 84, B1, 00, 00, 00, FF, 75, 10, 56, FF, 75, 08, E8, 11, FE, FF, FF, 89, 45, E4...
 
[+]

Entropy:
6.0739

Developed / compiled with:
Microsoft Visual C++

Code size:
159 KB (162,816 bytes)

The file gatesnapper.dll has been discovered within the following programs.

gate snapper  by Yontoo Technology, Inc.
This is browser adware. It installs in the user's web browser and while running will display unwanted ads from malicious software and other adware. It is bundled through download managers.
gatesnapper.com/support
87% remove it
 
Powered by Should I Remove It?

The file gatesnapper.dll has been seen being distributed by the following URL.

Remove gatesnapper.dll - Powered by Reason Core Security